4 ms·
I don't explicitly work in security, but I've had a handful of arguments in the past where I've discovered a serious vulnerability, and been told either by my m
by EnderMB 7y ago
I don't explicitly work in security, but I've had a handful of arguments in the past where I've discovered a serious vulnerability, and been told either by my managers or by a client that it is low-priority.
Sometimes, the vulnerability was then exploited, and what shocked me was that people were okay with this. I won't name names, but one marketing department I worked with was happier to suffer a customer data leak over having to spend budget during the end of the year to fix the issue. I later learned that the IT department got in trouble for allowing the error to happen, when the system was entirely managed by us and our sole point of contact was with someone in marketing that left their position because they didn't get on with IT.
If there's one thing I learned, it's that the ultimate currency in business is risk, and that the software/IT industry lacks the power to really do anything when a company is found to be negligent. For many, the risk of "being caught" is worth not spending money on preventative issues, and ultimately there's absolutely nothing we can do about it outside of covering our asses when the finger is pointed our way.
You only need to look at the Panera Bread security breach to see that all the badmouthing on Twitter did nothing to stop the company from painting its own narrative. Hell, the WordPress theme/plugin company Pipdig was caught ddosing its rivals with their software, and all they had to do was lay low on social media for a month and lie in a blog post. The worst part was that their non-techie customers were all too happy to back them up, meaning that the WordPress security community had zero clout to really do anything.
I have the utmost respect for anyone that works in security, because you're fighting a battle that no one wants to win, and is often a battle where it feels your partners are silently rooting for the other side.
- teekert 7y agoThat's why EU laws to punish such negligence are a good thing. They increase the risk for companies, to something very specific.
- EnderMB 7y agoI'm in the UK, so all of these companies are either primarily based in the EU, or do business here. GDPR has put some fear back in, but even today there are loads of companies that simply don't give a shit, and will happily risk it all so that they don't have to adapt their practices from years ago. In my experience, smaller companies are the worst offenders, because they know they are small fry. Pipdig are a UK company, and have been actively caught using malicious code with proof, yet they're still running without a care in the world. This all happened recently too, so it's not like it's a pre-GDPR or pre-ICO crackdown issue.
- ownagefool 7y agoI think CISOs are a bit more worried than they were before, but CFOs still refuse to pay for individuals. It's the old Capex vs Opex and random jealously that flies around the market, combined with a lack of skills that leads to outsourcing to consultancies that sell snake oil. It'll remain crap I imagine.
- coldcode 7y agoI worked at a healthcare company in the US (we provided HIPAA data connections between insurance and providers) and discovered all the production passwords were storied in a text file in the code repo half the company had access to. The CTO told me "we trust our employees". There was also no auditing on who access the DB and servers, and they never changed the passwords because the chief architect did not want to remember anything.
- rpmisms 7y agoDid you work at my current company? Because that's Exactly what happens here. Also, I'm so sorry you had to touch EDI, if you did.
- SamuelAdams 7y agoI worked at a retailer (not Target) that did something similar. Once Target got breached in 2014, they mandated security training and began making changes to some things in the org. This was one - instead of storing those passwords in plain-text, they were encrypted. So people encrypted them, commited them into the repositories, and deployed the now encrypted files to production. Cool, right? They didn't actually change the passwords, since that would break too many things at once. So you could just look at the git history to get the plain text password. Or debug the application locally. Security theater all day. Sigh.
- EnderMB 7y agoThere's something both comforting and absolutely terrifying that everyone has similar stories of software negligence. I would love to see a whistle-blower company formed, where you could report software engineering malpractice, and be compensated and/or protected from being punished. Not necessarily a union, but an industry body that could verify your security concerns and either "out" a company for punishing you, or provide you x months of work and a reference to compensate the termination of your employment.